Cloud & Cybersecurity

Vendor-neutral, source-based reference materials on GCC cloud compliance, data sovereignty, and cloud data residency requirements,

including the SAMA Cyber Security Framework (CSF), NCA Essential Cybersecurity Controls (ECC), and the UAE Personal Data Protection Law (PDPL)

Currently covering GCC regions. Expanding.

amina . amina .

Saudi Cybersecurity: Non-CNI vs CNI — What’s the Difference?

Saudi Arabia’s National Cybersecurity Authority (NCA) has rolled out updated minimum cybersecurity controls for private sector organizations, whether they’re classified as Critical National Infrastructure (CNI) or Non-CNI. Understanding the differences is essential for compliance, risk management, and digital resilience.

Read More
amina . amina .

Saudi NCA Cybersecurity Controls for Non-Critical National Infrastructure Private Sector Entities (2025-2026)

Saudi Arabia’s National Cybersecurity Authority (NCA) has published a new baseline cybersecurity framework specifically for Non-Critical National Infrastructure (Non-CNI) private sector entities covering 2025–2026. This regulatory update marks a major shift: cybersecurity is now a mandatory compliance obligation for private companies of all sizes operating in the Kingdom — even those without sensitive infrastructure.

Read More
amina . amina .

UAE PDPL vs DIFC vs ADGM

The UAE operates three legally distinct data protection regimes—PDPL, DIFC, and ADGM—each tied to sovereign jurisdiction, not geography. This reference explains how those regimes affect cloud sovereignty, data residency, cross-border transfers, and regulator authority for practitioners designing compliant cloud and data architectures.

Read More
amina . amina .

Saudi Central Bank (SAMA) Cyber Security Rules: Official Source

This page consolidates official cybersecurity rules and frameworks issued by the Saudi Central Bank (SAMA), relevant to both SAMA-regulated financial institutions and cloud or third-party providers supporting them. It highlights authoritative sources, cloud-relevant sections of the SAMA Cyber Security Framework, and the distinction between official regulatory text and derived interpretations.

Read More
amina . amina .

A Complete Guide for Foreign Financial Companies Entering Saudi Arabia (2026)

Saudi Arabia offers massive fintech and banking growth under Vision 2030, but success depends on meeting strict SAMA and PDPL compliance expectations — especially around in-Kingdom data storage, DR, cloud design, regulator access, and vendor governance. This article breaks down key regulatory frameworks, common mistakes foreign companies make, cost expectations, and how to build Saudi-ready architecture from day one.

Read More